Opens in a new tab
vmblog logo 2024 wht (updated)

Conifers 2026 Predictions: Agentic Attacks, Security AGI, and the New SOC Model

Share: 

David Marshall | Published: November 20, 2025

   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Tom Findling, CEO, Conifers

The coming year will define how AI reshapes cybersecurity for both attackers and defenders. Attackers are moving from human-led efforts to AI-driven operations, while defenders are working quickly to use AI for detection and response. As AI becomes more important, the role of humans is changing, and security operations centers are adapting. With new types of attacks and early signs of security artificial general intelligence (AGI), 2026 will be a key year for how organizations strengthen their defenses.

Agentic Attacks Go Operational

Hackers are using AI agents that can adapt to defenses and perform complex task sequences to enable an attack. These AI systems will move from experimental to fully operational by 2026. Agentic AI malware will explore environments, adapt to thresholds, and exploit vulnerabilities faster than any human-driven campaign, and it will be able to run continuously to overload static defenses. As a result, security teams using static thresholds or manual investigation will find their tools obsolete. The next generation of defenses will need to include AI systems that can learn, reason, and respond in real time.

Security AGI Takes Its First Real Steps

Security AGI describes systems that understand the entire environment of an organization, including assets, controls, behavioral patterns, and previous incidents. This development will begin to happen in 2026. These systems will integrate institutional knowledge with global threat intelligence systems to take action with minimum human involvement. Like the early days of autonomous driving, they will still require human supervision, but their ability to manage nearly all security scenarios will alter the economics of defense. Security teams will no longer spend their time on investigations, but rather on verifying and improving complex, AI-driven outcomes.

The SOC Workforce Turns into AI Enablers

The SOC will enter a new phase in 2026. AI systems will handle the multiple stages of detection and response, while human analysts will focus on model training, oversight, and performance measurement. Roles centered on manual triage or routine investigation will fade. A smaller group of highly skilled professionals who understand how to guide and evaluate AI behavior will emerge. These new analysts will earn more, think more strategically, and spend their time on quality assurance and escalation management. The SOC will operate as a control hub where people and AI systems work in tandem.

Industry-Specific Security AI Agents Take Hold

Specialized security agents designed for particular sectors will gain momentum in 2026. Oil and gas operators, airport authorities, and financial institutions are already seeking AI tuned to their unique needs. These agents will interpret data through the context of industry protocols, regulatory frameworks, and risk priorities. They’ll enhance detection and response precision, reducing false positives that stem from generic models. Demand is especially strong in fraud detection and operational technology environments, where the mix of legacy systems and critical uptime creates distinctive risks. This wave of specialization will mark the next stage in cybersecurity AI, where effectiveness depends on the depth of domain knowledge rather than broad capability alone.

Strategic Adaptation for the Year Ahead

The changes described in these predictions aren’t just technical. They’ll push security teams to rethink how they work and which skills matter most. Successful organizations will treat AI as an additional tool that gains strength from human judgment and careful oversight. Building resilience in 2026 means using AI where it adds clear value and ensuring teams stay in control. The aim is to understand how human expertise and AI systems can work together to strengthen defenses.

##

ABOUT THE AUTHOR

tom findling 

Tom Findling is a strategic leader with a proven track record in go-to-market (GTM), product and data science. Having served as Chief Customer Officer at IntSights (acquired by Rapid7) and subsequently as Senior Director of Product at Rapid7, he brings a unique blend of strategic vision and execution to the table running large scale operations. Additionally, he led GTM and product roles at VMware and SUS.